T1087 - Account Discovery is a mitre_attack tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed April 21, 2026; most recent activity July 13, 2026.
In late 2025 and early 2026, a new data-wiping malware known as Lotus Wiper was identified targeting the energy and utilities sector in Venezuela. The malware was uploaded to a public platform in mid-December 2025 and…
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
Microsoft has reported a significant cyberattack by the threat actor Storm-2949, which exploited Microsoft Entra ID accounts to conduct a large-scale data theft from Microsoft 365 and Azure environments. The attack…
Cybercriminals are increasingly using OAuth client ID spoofing to conduct account enumeration against Microsoft Entra, the identity management service. This method allows attackers to infer username and password…
ServiceNow confirmed a data breach on June 9, 2026, after attackers exploited an unauthenticated API endpoint, allowing access to sensitive customer data. The vulnerability, found in the endpoint…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
On June 7, 2026, the French government's encrypted messaging platform Tchap was breached due to an account hijacking. The attack was executed through social engineering, compromising a user account linked to Tchap's…
Anthropic published an analysis on June 3, 2026, detailing 832 accounts banned for malicious cyber activity from March 2025 to March 2026. The report mapped these activities to the MITRE ATT&CK framework, revealing that…
A threat actor utilized AI-generated malware to infiltrate a network on June 3, 2026, employing a PowerShell script created through a method called vibe coding. This technique allows attackers to generate custom scripts…